Trusence Every claim has a source
Last updated 28 September 2026 Search Türkçe
← All stories
Security

Cloudflare patches cross-tenant flaw in Containers and Sandboxes

The fix closes a route that could have let one customer recover another account’s residual data.

Updated 28 September 2026

Cloudflare patched a cross-tenant flaw affecting Containers and Sandboxes that could let a Workers Paid customer retrieve remnants left by another account on the same physical machine. The cause was shared storage reassigning 64 KiB blocks without wiping them first. During testing, remnants surfaced at 18 of 24 container placements and on 20 of 22 nodes. Cloudflare says its review found no evidence that customer data had been exposed through this method. It completed its mitigation work by September 19, 2026.

Why it matters

For customers sharing a host, the flaw meant data left behind by one account could have crossed into another account’s reach. Cloudflare says it completed mitigation and found no evidence that customer data was exposed through this method.

Sources

  • BleepingComputer